<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gsma on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/gsma/</link><description>Recent content in Gsma on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/gsma/index.xml" rel="self" type="application/rss+xml"/><item><title>GSMA NESAS</title><link>https://lesitedefrancois.be/en/compliance/gsma-nesas/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/gsma-nesas/</guid><description>&lt;p&gt;The &lt;strong&gt;GSMA Network Equipment Security Assurance Scheme (NESAS)&lt;/strong&gt; is a &lt;strong&gt;voluntary, global&lt;/strong&gt; security assurance framework jointly led by the &lt;strong&gt;GSMA&lt;/strong&gt; and &lt;strong&gt;3GPP&lt;/strong&gt;. It was established to provide a universal, industry-driven security evaluation for mobile network equipment — primarily targeting 4G/LTE and 5G infrastructure — that avoids the fragmentation of country-specific security requirements. NESAS operates through two complementary components: first, an &lt;strong&gt;audit of the vendor&amp;rsquo;s development and product lifecycle processes&lt;/strong&gt; (covering secure design, implementation, testing, and vulnerability handling), conducted by GSMA-appointed auditing organizations; second, a &lt;strong&gt;product evaluation&lt;/strong&gt; against 3GPP-defined Security Assurance Specifications (SCAS), performed by ISO/IEC 17025 accredited security test laboratories. The GSMA manages scheme governance (accreditation, dispute resolution, publication of results), while 3GPP&amp;rsquo;s SA3 working group defines the technical security requirements and test cases in SCAS documents. The scheme is currently at &lt;strong&gt;NESAS v3.0&lt;/strong&gt; (specifications published early 2025), which introduces revised security requirements and expands coverage to include virtualized network functions. NESAS is &lt;strong&gt;voluntary&lt;/strong&gt; — no government mandates it — but it is increasingly referenced by national 5G security reviews and procurement requirements (including the EU 5G Toolbox), and major operators use NESAS assessment results as a procurement criterion. Evaluated vendors and their results are publicly listed on the GSMA website.&lt;/p&gt;</description></item></channel></rss>